Vulnerabilities > Samsung

DATE CVE VULNERABILITY TITLE RISK
2025-02-04 CVE-2025-20891 Out-of-bounds Read vulnerability in Samsung Android 12.0/13.0/14.0
Out-of-bounds read in decoding malformed bitstream of video thumbnails in libsthmbc.so prior to SMR Jan-2025 Release 1 allows local attackers to read arbitrary memory.
local
low complexity
samsung CWE-125
5.5
2025-02-04 CVE-2025-20892 Unspecified vulnerability in Samsung Android 13.0/14.0
Protection Mechanism Failure in bootloader prior to SMR Jan-2025 Release 1 allows physical attackers to allow to execute fastboot command.
low complexity
samsung
5.9
2025-02-04 CVE-2025-20893 Unspecified vulnerability in Samsung Android 14.0
Improper access control in NotificationManager prior to SMR Jan-2025 Release 1 allows local attackers to change the configuration of notifications.
local
low complexity
samsung
5.1
2025-02-04 CVE-2025-20904 Out-of-bounds Write vulnerability in Samsung Android 12.0/13.0/14.0
Out-of-bounds write in mPOS TUI trustlet prior to SMR Feb-2025 Release 1 allows local privileged attackers to cause memory corruption.
local
low complexity
samsung CWE-787
6.7
2025-02-04 CVE-2025-20905 Out-of-bounds Read vulnerability in Samsung Android 12.0/13.0/14.0
Out-of-bounds read and write in mPOS TUI trustlet prior to SMR Feb-2025 Release 1 allows local privileged attackers to read and write out-of-bounds memory.
local
low complexity
samsung CWE-125
6.7
2025-02-04 CVE-2025-20907 Unspecified vulnerability in Samsung Android 12.0/13.0
Improper privilege management in Samsung Find prior to SMR Feb-2025 Release 1 allows local privileged attackers to disable Samsung Find.
local
low complexity
samsung
4.4
2024-12-03 CVE-2024-49410 Out-of-bounds Write vulnerability in Samsung Android 12.0/13.0
Out-of-bounds write in libswmfextractor.so prior to SMR Dec-2024 Release 1 allows local attackers to execute arbitrary code.
local
low complexity
samsung CWE-787
7.8
2024-12-03 CVE-2024-49411 Path Traversal vulnerability in Samsung Android 12.0/13.0
Path Traversal in ThemeCenter prior to SMR Dec-2024 Release 1 allows physical attackers to copy apk files to arbitrary path with ThemeCenter privilege.
low complexity
samsung CWE-22
4.6
2024-12-03 CVE-2024-49413 Improper Verification of Cryptographic Signature vulnerability in Samsung Android 13.0/14.0
Improper Verification of Cryptographic Signature in SmartSwitch prior to SMR Dec-2024 Release 1 allows local attackers to install malicious applications.
local
low complexity
samsung CWE-347
7.8
2024-12-03 CVE-2024-49414 Unspecified vulnerability in Samsung Android 12.0/13.0
Authentication Bypass Using an Alternate Path in Dex Mode prior to SMR Dec-2024 Release 1 allows physical attackers to temporarily access to recent app list.
low complexity
samsung
2.4